PT-2026-3261 · Dive · Dive
Tonycrane
·
Published
2026-01-16
·
Updated
2026-02-09
·
CVE-2026-23523
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dive versions prior to 0.13.0
Description
Dive is an open-source MCP Host Desktop Application that integrates with function-calling LLMs. A crafted deeplink can install an attacker-controlled MCP server configuration without sufficient user confirmation, potentially leading to arbitrary local command execution on the victim’s machine. The vulnerability is related to the handling of deeplinks and the installation of MCP server configurations.
Recommendations
Update Dive to version 0.13.0 or later.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dive